15 essential bug bounty commands
thexssrat.podia.com/full-hou…
1. subfinder -d
target.com -all -recursive
# Enumerate subdomains
2. assetfinder --subs-only
target.com
# Find related assets
3. amass enum -passive -d
target.com
# Passive recon at scale
4. httpx -l subs.txt -status-code -title -tech-detect
# Check live hosts + tech stack
5. naabu -l subs.txt -top-ports 1000
# Fast port scanning
6. nmap -sC -sV -p-
target.com
# Deep service enumeration
7. gau
target.com
# Fetch historical URLs
8. waybackurls
target.com
# Discover old endpoints
9. katana -u
target.com -jc -kf -ef css,png,jpg
# Modern web crawler
10. gf xss urls.txt
# Pattern-based vulnerability filtering
11. dalfox url
target.com
# Automated XSS scanning
12. nuclei -l urls.txt -severity high,critical
# Template-based vuln scanning
13. ffuf -u
target.com/FUZZ -w wordlist.txt
# Directory & parameter fuzzing
14. sqlmap -u "
target.com?id=1" --batch
# Automated SQLi testing
15. MoveYourAssDUMMY
# Manual testing & request manipulation